codebase-audit

codebase-audit is a skill for Claude Code from mhylle/claude-skills-collection. It costs 0 tokens per session (3,273 once invoked), scanned A, original, MIT.

A workflow for conducting a thorough, adversarial review of an entire codebase. It divides the repository into parts, reviews them, and combines the findings into a risk register and report.

In plain words
What is it for?
Use it for onboarding, due diligence, or a full technical-debt review when comprehensive codebase coverage is needed.
Why use it?
It helps reveal security, quality, and maintenance risks across the whole repository rather than only in recently changed files.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: mentions CLAUDE.md; mentions subagents.

Part of the devflow plugin — 38 skills, 13 agents, 5 hooks shipped together

Good fit Use it for onboarding, due diligence, or a full technical-debt review when comprehensive codebase coverage is needed.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/mhylle/claude-skills-collection/codebase-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add mhylle/claude-skills-collection --skill codebase-audit
Clone the repo
git clone --depth 1 https://github.com/mhylle/claude-skills-collection

Made for: Claude Code.

Or install devflow, the plugin that ships this one along with the rest of its 38 skills, 13 agents, 5 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for codebase-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/mhylle/claude-skills-collection/codebase-audit.svg)](https://agentmods.dev/skills/mhylle/claude-skills-collection/codebase-audit)
Your own site
<a href="https://agentmods.dev/skills/mhylle/claude-skills-collection/codebase-audit"><img src="https://agentmods.dev/badge/skills/mhylle/claude-skills-collection/codebase-audit.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,273 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.03273
Opus 5 $0.00000 $0.01636
Sonnet 5 $0.00000 $0.00655
Haiku 4.5 $0.00000 $0.00327

Measured 8d ago against content hash ba2707559a63, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

codebase-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/codebase-audit/SKILL.md · 225 lines

How it starts

The opening of the file, as written. The whole thing — 225 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Codebase Audit

Long-running comprehensive adversarial audit. Orchestrates per-partition reviews through /adversarial-reviewer --codebase, then synthesizes findings into a written report. Designed for methodical full coverage, not strategic sampling — use when the user wants the whole thing reviewed and is willing to spend the tokens and time.

Positioning

Skill What it does Coverage Output When
/code-review Per-phase quality gate Changed files Verdict + notes During implementation
/adversarial-reviewer (diff) Hostile pre-merge review Changed files BLOCK/CONCERNS/CLEAN Before a merge
/adversarial-reviewer --codebase Adversarial sample of repo 5-10 files per persona HIGH/MEDIUM/LOW-RISK + most-concerning area Quick whole-repo sanity check
/codebase-audit Methodical full audit Every partition Written report + risk register Onboarding / due diligence / tech-debt review
/code-quality-audit Metrics: coverage, complexity, cycles, mutation Whole repo (metric-based) Numeric gate Quantitative health

Pair codebase-audit with code-quality-audit for a complete picture: this skill gives you the qualitative adversarial read; code-quality-audit gives you the quantitative one.

Usage

/codebase-audit                        # Audit CWD
/codebase-audit src/                   # Scope to a subtree
/codebase-audit --resume               # Pick up from last checkpoint
/codebase-audit --only api             # Re-run a specific partition
/codebase-audit --force                # Ignore existing partition reports (re-review everything)

Expect 200K-500K tokens and 30-60 minutes of wall clock for a typical ~500-file repo. This is a deliberate investment. Confirm with the user before kicking off if the cost would surprise them.

Workflow

Step 1: Scope and map

Determine the scope root (path argument, or CWD). Build the map:

Read the full file on GitHub · 225 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 225 lines · 0 tokens per session scan A ba2707559a63

Subscribe to this mod's changes

codebase-audit is a skill published in the GitHub repository mhylle/claude-skills-collection (18 stars, last pushed 5d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,273 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.